
ShipTime: Discounted Shipping Rates Security & Risk Analysis
wordpress.org/plugins/shiptime-discount-shippingThis plugin provides real-time discounted shipping rates from ShipTime. You can enable real-time rates at check-out and your customers can select from …
Is ShipTime: Discounted Shipping Rates Safe to Use in 2026?
Generally Safe
Score 92/100ShipTime: Discounted Shipping Rates has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The shiptime-discount-shipping plugin version 1.1.1 exhibits a concerning security posture primarily due to a significant lack of authorization checks on its exposed entry points. All 5 identified entry points, comprising 1 AJAX handler and 4 REST API routes, are unprotected. This means that any unauthenticated user could potentially interact with these functions, leading to unintended actions or data exposure. While the code analysis reveals good practices in output escaping (91% properly escaped) and a lack of dangerous functions or file operations, the unprotected entry points represent a critical weakness. The absence of nonce checks and capability checks further exacerbates this risk, as there are no mechanisms to verify user intent or permissions.
The plugin's vulnerability history is clean, with no recorded CVEs. This is a positive indicator, suggesting that either the plugin has not been targeted or its current codebase, despite its access control issues, has not yet presented exploitable vulnerabilities. However, this lack of history should not be interpreted as a guarantee of future safety, especially given the readily available attack surface. The total absence of taint analysis results is neutral; it doesn't indicate a problem but also doesn't offer reassurance regarding potential data handling vulnerabilities.
In conclusion, while the plugin demonstrates strengths in output sanitization and avoids common dangerous code patterns, its security is severely undermined by the complete lack of authentication and authorization on its AJAX and REST API endpoints. This creates a substantial risk that could allow unauthorized users to manipulate plugin functionality. It is strongly recommended to implement proper authentication and capability checks on all exposed entry points before further usage.
Key Concerns
- Unprotected AJAX handler
- Unprotected REST API routes (4)
- No nonce checks
- No capability checks
- SQL queries not fully prepared (60% prepared)
ShipTime: Discounted Shipping Rates Security Vulnerabilities
ShipTime: Discounted Shipping Rates Code Analysis
SQL Query Safety
Output Escaping
ShipTime: Discounted Shipping Rates Attack Surface
AJAX Handlers 1
REST API Routes 4
WordPress Hooks 9
Maintenance & Trust
ShipTime: Discounted Shipping Rates Maintenance & Trust
Maintenance Signals
Community Trust
ShipTime: Discounted Shipping Rates Alternatives
API2Cart Live Shipping 4 Woocommerce
api2cart-live-shipping-4-woocommerce
This plugin allows to use of real-time shipping rates provided by third-party shipping services.
Gelato Integration for WooCommerce
gelato-integration-for-woocommerce
Sell globally, print locally with 100+ production hubs in 32 countries
Ship Discounts
ship-discounts
Offer your customers shipping services with real-time quotes. Need a livraisonsarabais.com / shipdiscounts.ca account
Weight Based Shipping Table Rate for WooCommerce – Flexible Shipping
flexible-shipping
Weight based shipping methods for WooCommerce. Flexible shipping with table rate rules by cart weight and order value. Accurate rates at checkout.
WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels
print-invoices-packing-slip-labels-for-woocommerce
Auto-generate and attach WooCommerce PDF invoices and packing slips to order emails with customizable templates & bulk print options.
ShipTime: Discounted Shipping Rates Developer Profile
1 plugin · 100 total installs
How We Detect ShipTime: Discounted Shipping Rates
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/shiptime-discount-shipping/app/js/shiptime-shipping.js/wp-content/plugins/shiptime-discount-shipping/app/css/shiptime-shipping.css/wp-content/plugins/shiptime-discount-shipping/app/js/shiptime-shipping.js/wp-content/plugins/shiptime-discount-shipping/app/js/shiptime-shipping.js?ver=/wp-content/plugins/shiptime-discount-shipping/app/css/shiptime-shipping.css?ver=HTML / DOM Fingerprints
shiptime-shippingshiptime_shipping_ajax_object